CVE-2020-35839

HIGH WAF: High
CVSS 8.1 Published: 2020-12-30
CWE-79

Certain NETGEAR devices are affected by Stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, XR500 before 2.3.2.56, XR700 before 1.0.1.10, and RAX120 before 1.0.0.78.

WAF Coverage Analysis

Cross-Site Scripting (XSS) High WAF Coverage

OWASP: A03:2021 Injection

941xxx - XSS / XXE

Affected Software

VendorProductVersion
netgeard7800_firmwareup to 1.0.1.56
netgearr7500v2_firmwareup to 1.0.3.46
netgearr7800_firmwareup to 1.0.2.68
netgearr8900_firmwareup to 1.0.4.28
netgearr9000_firmwareup to 1.0.4.28
netgearxr500_firmwareup to 2.3.2.56
netgearxr700_firmwareup to 1.0.1.10
netgearrax120_firmwareup to 1.0.0.78

References

Back to CVE Database